Detect Attacks with Sysmon


Where was the file downloaded by the victim (C:*******)
I think that’s the answer to this question, what am I doing wrong?

1 Like

the attacker got a shell with that file you entered and then download a file to pr******** es******** ?

1 Like

i got it, thanks for advice.

1 Like